WHOis Team
2013-03-20 • Mcafee • South Korean ‘Whois Team’ attacks
Whois Team is a name that emerged in March 2013 when attackers claimed responsibility for destructive "Dark Seoul" attacks against South Korean banks and broadcasters, defacing at least one victim website and deploying disk-wiping malware; contemporaneous reporting was initially unable to determine whether a nation-state was responsible. Later analysis connected Whois Team to a second group calling itself the NewRomanic Cyber Army Team, which claimed the 2013 attacks and left messages and imagery closely resembling those later used in the November 2014 Sony Pictures intrusion, contributing to the public case for North Korean responsibility for that attack as part of an espionage campaign researchers traced back to 2009. Separate research cautioned that the Whois Team name and its listed handles could represent a false flag, noting that a South Korean white-hat capture-the-flag team also uses the "WhoIs" moniker, and that no additional attacks under the Whois Team name were subsequently observed.
-
60
Related Actors
-
690
Related Reports